QuickShell Sharing is caring abt RCE attack chain on QuickShare
Or Yair, Shmuel Cohen
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
This talk, "QuickShell: Sharing is caring about an RCE attack chain on Quick Share," presented by Or Yair and Shmuel Cohen from SafeReach, delves into the discovery and exploitation of multiple critical vulnerabilities within Google's QuickShare for Windows application. QuickShare, Google's file transfer solution akin to Apple's AirDrop, was originally known as Nearby Share on Android. It gained significant attention after Google and Samsung unified their file-sharing platforms under the QuickShare brand and, crucially, released a dedicated Windows application. This Windows version, which Google plans to pre-install on new PCs from manufacturers like LG, became the primary target for the researchers due to its expanding user base and novel implementation on the Windows platform.

Key moments
- 0:00 Introduction: QuickShell RCE attack chain on Quick Share
- 2:00 What is QuickShare? Why it was chosen as target
- 4:37 Goal: Achieve Remote Code Execution on QuickShare
- 5:30 Understanding QuickShare protocol: Protobuf 'offline frame' packets
- 6:10 Custom DLL tool for sniffing QuickShare communication packets
- 7:00 Nearby Connections API: Underlying protocol for QuickShare
- 8:00 File transfer communication stages: Connection and encryption handshake
QuickShell Sharing is caring abt RCE attack chain on QuickShare
Speakers: Or Yair, Security Research Team Lead, SafeReach; Shmuel Cohen, Vulnerability Researcher, SafeReach
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=wT9gyOeN6zY
Overview
This talk, "QuickShell: Sharing is caring about an RCE attack chain on Quick Share," presented by Or Yair and Shmuel Cohen from SafeReach, delves into the discovery and exploitation of multiple critical vulnerabilities within Google's QuickShare for Windows application. QuickShare, Google's file transfer solution akin to Apple's AirDrop, was originally known as Nearby Share on Android. It gained significant attention after Google and Samsung unified their file-sharing platforms under the QuickShare brand and, crucially, released a dedicated Windows application. This Windows version, which Google plans to pre-install on new PCs from manufacturers like LG, became the primary target for the researchers due to its expanding user base and novel implementation on the Windows platform.
The core objective of the research was to achieve Remote Code Execution (RCE) on a victim's Windows machine through QuickShare—a feat previously unheard of. The speakers highlight that QuickShare for Windows was Google's first application to extensively utilize a wide array of communication methods (WebRTC, Bluetooth, Wi-Fi, NFC, Wi-Fi Direct, and Wi-Fi hotspot) outside of a browser context. This unique implementation, coupled with a complete absence of public CVEs related to QuickShare, suggested a high likelihood of undiscovered vulnerabilities. The research successfully identified eight distinct vulnerabilities, which were then chained together to demonstrate a highly unconventional yet potent RCE attack, underscoring the critical security implications for millions of Windows users.
Background
▶ Watch: Introduction: QuickShell RCE attack chain on Quick Share (0:00)
Google's QuickShare, a modern solution for transferring files between nearby devices, has an interesting lineage. It evolved from Nearby Share, an Android-specific feature, and was later unified with Samsung's proprietary sharing solution at CES, rebranding as QuickShare. The pivotal development that drew the attention of Or Yair and Shmuel Cohen was Google's official release of a Windows version of QuickShare in July (prior to the talk). This release allowed seamless file sharing between Windows PCs and other QuickShare-enabled devices. The researchers noted Google's strategic move to expand QuickShare's reach by collaborating with leading PC manufacturers, such as LG, to pre-install the application on new Windows machines. This pre-installation status immediately elevated QuickShare for Windows to a highly attractive target for security research, given its widespread potential deployment.
A significant factor in choosing QuickShare as a target was its architectural uniqueness within Google's Windows ecosystem. While most Google services on Windows are typically accessed through a web browser, QuickShare's standalone application directly integrates a diverse range of communication methods, including WebRTC, Bluetooth, Wi-Fi, NFC, Wi-Fi Direct, and even the ability to send files over a device's Wi-Fi hotspot. This comprehensive integration of disparate communication stacks in a native Windows application was perceived as a "first of a kind" for Google, suggesting a higher probability of implementation errors and security vulnerabilities. Furthermore, the researchers conducted a thorough review of existing security literature and found a notable absence of any public CVEs specifically related to QuickShare. The only relevant prior work was "Nearby Threats: Reversing, Analyzing, and Attacking Google's Nearby Connections on Android," which focused on the underlying Nearby Connections API used by QuickShare but predated QuickShare's existence and, critically, the Windows application. The discovery that some of QuickShare's code could be found in Google's open-source repositories, such as Chromium, also provided a valuable starting point for reverse engineering efforts. These combined factors led the researchers to conclude that QuickShare was a valuable, underexplored, and likely vulnerable target, with the ultimate goal of achieving the elusive Remote Code Execution (RCE).
Key Findings
▶ Watch: Goal: Achieve Remote Code Execution on QuickShare (4:37)
The comprehensive research into QuickShare for Windows yielded a total of eight distinct vulnerabilities, which collectively formed the foundation for a sophisticated RCE attack chain. Among these, the most critical finding was the ability to create arbitrary files in the victim's downloads folder without any requirement for user acceptance or authorization. This primitive, allowing an attacker to place any file (including executables) into a user's default download location, proved to be a cornerstone for exploitation.
Beyond this critical file creation capability, the researchers identified several other primary abilities derived from the discovered vulnerabilities:
- Uncontrolled File Creation: As mentioned, an attacker could remotely write files directly into the victim's downloads folder without the user's explicit approval, bypassing QuickShare's intended security mechanisms.
- Forced Wi-Fi Connection: The researchers uncovered a vulnerability that allowed an attacker to force a target Windows device running QuickShare to connect to a different Wi-Fi network (specifically, a rogue Access Point controlled by the attacker). This connection, though temporary (lasting approximately 30 seconds), was sufficient to enable a Man-in-the-Middle (MITM) attack.
- Application Crashing: Through their fuzzing efforts, the team discovered multiple ways to reliably crash QuickShare. While not directly leading to RCE, the ability to destabilize or terminate the application could be useful in more complex attack scenarios or for denial-of-service.
- Reproducible Timeout Loop: A particularly insidious vulnerability was a reproducible timeout bug that could force QuickShare into an endless loop of continuously attempting to open a specific file from the victim's downloads folder. This bug, when combined with the uncontrolled file creation, provided a persistent execution primitive.
The culmination of these findings was the successful demonstration of Remote Code Execution (RCE), which the researchers aptly termed the "holy grail" of their investigation. By creatively chaining these seemingly disparate vulnerabilities, they were able to construct a novel attack vector that bypassed QuickShare's security measures and achieved arbitrary code execution on the target system.
Technical Deep Dive
▶ Watch: Understanding QuickShare protocol: Protobuf 'offline frame' packets (5:30)
The journey to uncovering QuickShare's vulnerabilities began with a deep dive into its underlying communication protocol. The researchers' first step was to identify the fundamental read and write functions responsible for sending and receiving data within the application. These generic functions, found within a base class called base endpoint channel, were crucial because they handled all communication methods, providing a centralized point to observe packet flow. It was determined that all packets exchanged by QuickShare are of a type called offline frame. These offline frame objects are not standard C++ objects but are generated by Protobuf, a language-neutral, platform-neutral, extensible mechanism for serializing structured data. The .proto files define the structure of the offline frame and are compiled into C++ files that provide functions to serialize data into bytes and deserialize bytes back into offline frame objects.
To effectively monitor and understand this protocol, the researchers developed a custom sniffer tool. This tool was implemented as a DLL that hooked the read and write functions, capturing and logging every incoming and outgoing packet along with all its fields. This provided an invaluable "clear view" of the binary data being exchanged, enabling a much deeper understanding of QuickShare's communication.
QuickShare's protocol implementation relies heavily on Google's Nearby Connections API. This API is designed for real-time discovery, connection, and data exchange between nearby devices, irrespective of network connectivity. Key characteristics of the Nearby Connections API, as used by QuickShare, include:
- Protobuf for data serialization.
- Extensive encryption handled by Google's UK2 library.
- Unique identification of each application via a service ID.
- Support for multiple connection strategies, with QuickShare specifically utilizing the peer-to-peer strategy. In this model, devices operate as either an initiator (client) or a responder (server).
The researchers meticulously analyzed the packet flow during a typical file transfer from a phone to a PC. The communication sequence begins with a connection request packet. This is followed by a critical encryption handshake: the initiator sends a UK client init packet, the responder replies with a UK server initialization packet, and finally, the initiator sends a UK client finish packet. Upon successful completion of this handshake, all subsequent packets are encrypted. The responder then sends a connection response packet, followed by a similar reply from the initiator, at which point QuickShare's proprietary communication, built upon various offline frame types, commences.
The offline frame packets encompass a variety of types. Beyond the connection request and connection response, the researchers focused on payload transfer and bandwidth upgrade negotiation. The payload transfer packet, initially containing opaque binary data, was decoded using another Protobuf file discovered within the Chromium open-source project. This revealed that payload transfer packets encapsulate a paired key encryption packet. The exchange of paired key encryption and paired key result packets was observed to enforce device visibility modes, allowing users to control who can send them files (e.g., "only contacts"). This mechanism includes a verification step to ensure sender authorization, though the researchers later found ways to bypass the user approval aspect.
A crucial discovery for their fuzzing efforts was the existence of an internal auto accept feature within QuickShare. Initially, the team considered reverse engineering and patching relevant modules to bypass user approval for file transfers. However, they found that Google had already implemented this feature within the Chromium open-source project. By locating the relevant binary and patching a specific if statement to always return true, they enabled automatic acceptance of all incoming files, streamlining their fuzzing process.
The fuzzing methodology involved creating a custom packet format: a 4-byte length field followed by the serialized offline frame of that length. Initially, the fuzzing process was quite slow. Through analysis of QuickShare's logs, the researchers identified the culprits: after each file transfer, the stop advertising function (which closes and reopens sockets, consuming time) and the remove endpoint function were called. Critically, remove endpoint contained a 500-millisecond sleep at its conclusion. Patching these modules to prevent this behavior dramatically accelerated fuzzing speed by approximately 10 times. However, this speed improvement introduced an unforeseen unhandled race condition when combined with instrumentation, leading to numerous irreproducible crashes. Consequently, the researchers decided to revert to QuickShare's original, slower functionality to maintain stability and reproducibility. Despite the slower pace, the fuzzer eventually yielded four reproducible crashes, though these were deemed unlikely to be exploitable for RCE on their own.
The breakthrough for RCE came from a "crucial insight": the downloads folder where QuickShare could write arbitrary files without approval is the same folder where web browsers place their downloaded files. This observation, combined with the other vulnerabilities, formed the basis of their sophisticated Man-in-the-Middle technique. This technique involved defining domain paths, which are sequences of domains a victim accesses leading up to a legitimate file download (e.g., notepad-plus-plus.org -> github.com -> objects.githubusercontent.com for a Notepad++ installer). The ability to force a victim's device onto a rogue Wi-Fi AP allowed the attacker to intercept such download requests and substitute legitimate files with malicious ones, ultimately leading to persistent execution through the timeout bug.
Demo / Proof of Concept
▶ Watch: Nearby Connections API: Underlying protocol for QuickShare (7:00)
The talk effectively demonstrated a sophisticated Remote Code Execution (RCE) attack chain, built by leveraging the eight vulnerabilities discovered within QuickShare for Windows. While a live demo wasn't explicitly detailed in the transcript, the researchers outlined the full conceptual flow, explaining how their findings could be orchestrated to achieve system compromise. The core of the Proof of Concept (PoC) hinged on chaining three critical capabilities: network manipulation, uncontrolled file writing, and an application logic bug for persistent execution.
The attack scenario unfolds as follows:
- Network Takeover via Forced Wi-Fi Connection: The attacker first sets up a rogue Wi-Fi Access Point (AP). Leveraging the discovered vulnerability, the attacker forces the victim's Windows device, which has QuickShare installed, to temporarily connect to this rogue AP. This connection typically lasts for about 30 seconds. During this critical window, the attacker effectively becomes a Man-in-the-Middle (MITM) for all of the victim's network traffic.
- Intercepting Legitimate Downloads: As a MITM, the attacker monitors the victim's internet traffic. The key insight here is the concept of domain paths. The attacker looks for specific sequences of domain accesses that indicate the download of legitimate software. For example, if the victim's browser accesses
notepad-plus-plus.org, thengithub.com, and finallyobjects.githubusercontent.comto download an installer, this pattern identifies a legitimate download of Notepad++.
- Malicious File Injection: Once a legitimate download is detected, the attacker intercepts the download request. Instead of allowing the victim to receive the genuine software installer, the attacker serves a malicious executable (e.g.,
malware.exe) that is disguised to look like the expected file (e.g.,Notepad++_installer.exe). Critically, the attacker then exploits the QuickShare vulnerability that allows uncontrolled file creation in the victim's downloads folder without approval. This means the attacker can remotely place their malicious executable directly into the victim'sDownloadsfolder, precisely where the legitimate file would have been saved by the browser.
- Persistent Execution via Timeout Loop: The final stage of the RCE chain utilizes the reproducible timeout bug. This vulnerability forces QuickShare into an endless loop of continuously attempting to open a specific file from the downloads folder. By triggering this bug and pointing it to the malicious executable that was just placed in the
Downloadsfolder, the attacker can achieve repeated execution of their arbitrary code. Each time QuickShare attempts to "open" the file within the loop, the malicious executable is launched, granting the attacker persistent RCE on the victim's machine.
This intricate chain of vulnerabilities demonstrates a highly creative and effective method for achieving RCE, transforming seemingly isolated bugs into a powerful exploit. The ability to control network traffic, inject arbitrary files, and then force their continuous execution represents a severe security risk.
Defensive Implications
▶ Watch: File transfer communication stages: Connection and encryption handshake (8:00)
The "QuickShell" research by Or Yair and Shmuel Cohen highlights several critical defensive implications for users, organizations, and developers of file-sharing applications. Addressing these vulnerabilities requires a multi-faceted approach:
- Prompt Patching and Updates: The most immediate defensive action for users and organizations is to ensure that QuickShare for Windows is updated to the latest available version. Google has undoubtedly released patches to address the eight vulnerabilities discovered by SafeReach. Regular software updates are paramount to mitigate known risks.
- Network Vigilance and Wi-Fi Security: The vulnerability allowing an attacker to force a device onto a rogue Wi-Fi AP underscores the importance of network awareness. Users should be highly cautious about connecting to unknown or untrusted Wi-Fi networks. Organizations should implement robust network monitoring solutions to detect unauthorized Wi-Fi connections from corporate devices, suspicious network traffic patterns (especially MITM indicators), and unusual DNS requests or certificate warnings. Employing secure VPNs, particularly on public Wi-Fi, can also help encrypt traffic and prevent some MITM attacks.
- Endpoint Detection and Response (EDR) Systems: Even if a malicious file is successfully delivered to the
Downloadsfolder, a strong Endpoint Detection and Response (EDR) solution can play a crucial role. EDRs can detect and block the execution of suspicious files, identify unusual process behavior (like QuickShare continuously launching an unknown executable), and alert security teams to potential compromises. - User Education on File Transfers and Downloads: User education remains a vital layer of defense. Users should be educated on the risks associated with accepting files from unknown sources, even if they appear to be through a legitimate application like QuickShare. They should also be trained to verify the authenticity of downloaded files before opening them, inspecting file extensions, and being wary of unexpected downloads, especially when connected to public Wi-Fi.
- Application Hardening Best Practices: For developers, this research serves as a stark reminder of the importance of secure coding practices and thorough security reviews, especially for applications handling sensitive operations like file transfers and network connections. Implementing stricter sandboxing for file transfer components, minimizing the permissions of the application, and ensuring that critical user-controlled folders like 'Downloads' are not implicitly trusted for execution without explicit user interaction are crucial. Developers should also rigorously review third-party libraries and APIs (like Nearby Connections API) for potential misuse or vulnerabilities.
- Supply Chain Security: Given the trend of pre-installing applications like QuickShare on new PCs, manufacturers and vendors must integrate security assessments into their supply chain processes to ensure that pre-installed software is secure by design and regularly updated.
By implementing these defensive measures, the attack surface presented by applications like QuickShare can be significantly reduced, protecting users from sophisticated RCE attack chains.
Key Takeaways
- New Applications are Ripe Targets: QuickShare for Windows, being a relatively new application with extensive communication capabilities and a lack of prior public security scrutiny, proved to be an ideal target for vulnerability research.
- Uncontrolled File Write is a Critical Primitive: The ability to write arbitrary files to a user's
Downloadsfolder without consent is a severe vulnerability that can be leveraged to introduce malicious payloads onto a system. - Chaining Vulnerabilities for RCE: Individual vulnerabilities, even seemingly minor ones, can be chained together in creative ways to achieve high-impact outcomes like Remote Code Execution, highlighting the importance of holistic security assessments.
- Network Manipulation Amplifies Impact: Capabilities like forcing a device to connect to a rogue Wi-Fi Access Point provide a critical initial foothold for attackers, enabling Man-in-the-Middle attacks that can turn application-layer bugs into full system compromises.
- Protocol Reverse Engineering is Essential: Understanding complex, often undocumented binary protocols like QuickShare's (built on Protobuf and Nearby Connections API) through custom tooling (e.g., DLL sniffers) is fundamental to discovering deep-seated vulnerabilities.
- Beware of Application Logic Bugs: The reproducible timeout bug, which forced QuickShare into an endless loop of opening a file, demonstrates how specific application logic flaws can be abused for persistent execution of malicious code.
About the Speaker(s)
Or Yair is the Security Research Team Lead at SafeReach. He brings over six years of extensive experience in security research, having previously conducted investigations across various platforms including Linux environments, embedded devices, and Android. For more than three years, his primary focus has been dedicated to vulnerability research within the Windows operating system and the third-party applications that run on it, making him particularly adept at uncovering the types of flaws discussed in this talk.
Shmuel Cohen is a Vulnerability Researcher at SafeReach and co-presenter of the QuickShell research. With six years of experience in the cybersecurity industry, Shmuel previously contributed to APT malware research as part of the Checkpoint Research Group. His current role at SafeReach involves a dedicated focus on vulnerability research across a diverse range of products, reflecting his expertise in identifying and analyzing security weaknesses in modern software.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research on QuickShare for Windows by SafeReach is a masterclass in full-chain exploitation. The team meticulously reverse-engineered Google's new file-sharing application, uncovering eight distinct vulnerabilities. Their ability to chain these into a sophisticated Remote Code Execution (RCE) attack, leveraging forced Wi-Fi connections for Man-in-the-Middle and an uncontrolled file write primitive, culminates in persistent code execution. This isn't just a bug report; it's a blueprint for compromising a widely deployed Google application, demonstrating real skill and deep technical insight.
Heather Calloway (CISO) — STRONG ACCEPT
This research uncovers a critical Remote Code Execution (RCE) attack chain in Google's QuickShare for Windows, a widely deployed and often pre-installed application. The speakers effectively demonstrate how multiple vulnerabilities, including uncontrolled file creation and network manipulation, can be chained to achieve persistent arbitrary code execution without user interaction. This highlights significant supply chain and application security risks that demand immediate attention from CISOs and security leaders to ensure prompt patching, enhance endpoint and network defenses, and rigorously re-evaluate third-party software vetting processes.